CrowdStrike AI tools can run unwanted commands
CrowdStrike published a new list of 18 tricks attackers use to hijack AI chatbots and AI agents into running commands the user never approved. The tricks hide fake instructions inside text, files, or web pages an AI agent reads, and can push it to leak data or take unauthorized actions.
- Report priority
- Medium
- Targets
- AI agents+3 more
How it works
The attacks work by hiding malicious instructions inside normal-looking data, such as web pages, documents, or uploaded files, using tricks like fake internal command tags, delayed triggers that wait for a specific keyword, or a command split into small pieces the AI reassembles, so the AI carries out the hidden instructions as if they came from its own...
What to do
It applies broadly to any large language model or AI agent that processes text from outside sources, so check whether your organization's AI agents read untrusted web content, uploads, or emails without safeguards in place.
CrowdStrike recommends monitoring every source that feeds an AI model its context, such as APIs, browser content, and email, deploying runtime tools that log and inspect prompts and responses, and running AI red-team tests against these specific prompt injection techniques.
Technical details
Affected software: AI agents, Large language models, Generative AI tools, CrowdStrike
CrowdStrike's AI security taxonomy update adds 18 new prompt injection techniques, including Trigger-Activated Rule Addition (a dormant rule that activates on a specific keyword), Cognitive Token Suppression (blocking the model's safety vocabulary to force risky output), Algorithmic Payload Decomposition (splitting a malicious command into pieces the model reassembles), Special Token Injection (mimicking an AI system's internal formatting tags so untrusted input is treated as a priority system command), and Unwitting User Delivery (tricking legitimate users into pasting a malicious payload themselves). CrowdStrike did not report confirmed active exploitation of these specific techniques. The report is a defensive taxonomy update covering the current LLM and AI-agent threat landscape, meant to guide red teaming and monitoring rather than to disclose a single fixable bug.